Cookie Policy
Version 1.1 — in force from 12 August 2026. The only change from 1.0: the section about cookies on a payment checkout page is gone, because there is no checkout page.
A cookie is a small file a site asks your browser to keep. Some are how a website works at all. Others watch what you do. This page names every one we set, so you can tell which is which.
The short version
We set three cookies to make the site work. You cannot turn those off, because without them you cannot log in.
We set analytics cookies only if you allow it. Nothing analytics-related runs until you do — declining does not mean "run it quietly", it means the code never loads.
Change your mind whenever you like: Cookie settings, in the footer of every page.
Strictly necessary — always on
These carry no consent requirement in law, because you asked for the thing they do.
| Name | Set by | What it is for | How long |
|---|---|---|---|
session |
Deklarify | Keeps you logged in. Holds a random token, nothing about you. | 30 days, or until you log out |
oauth_state |
Deklarify | A one-time token that proves a "Sign in with Google" round trip came back from the same browser that started it. It is a security check against request forgery. | 5 minutes |
deklarify_consent |
Deklarify | Remembers what you chose on this page, so we do not ask again and so we can show you were asked. Holds your choice, the version of this policy, a timestamp, and a random reference. | 12 months |
deklarify_install_dismissed |
Deklarify | Not a cookie — browser storage. Records that you closed the "Install Deklarify" hint, so it stays closed. Holds nothing but that. | Until you clear your browser's site data |
session and oauth_state are HttpOnly and Secure: no script on the
page can read them, and they are never sent over an unencrypted connection.
That third one is worth a sentence. We have to store your refusal too. If you say no and we store nothing, we have no way to know you already answered, and you would get the banner on every page for the rest of your life.
Analytics — off unless you say yes
| Name | Set by | What it is for | How long |
|---|---|---|---|
_ga |
Google Analytics | Tells one browser from another, so two visits from you are not counted as two people | 2 years |
_ga_<id> |
Google Analytics | Keeps track of a single visit | 2 years |
If Google changes what it sets, we update this table.
What we get from it: which pages get read, roughly which country a reader is in, what device and browser, and whether people who arrive on a report go on to open another. What we do not get, and have not asked for: advertising audiences, cross-site tracking, or anything tied to your account.
We have turned off Google Signals, turned off ad personalisation in every region, turned off sharing your data with Google's own products and services, and set Google's retention to 14 months.
What we do not set
No advertising cookies. No social media pixels. No "marketing" category — there is nothing we would put in it, and offering an empty one would just be theatre.
Our fonts are served from our own domain rather than Google's, so loading a page does not tell Google you visited.
Changing your mind
- Cookie settings in the footer — the whole panel, any time, in one click.
- Your browser's own settings will block or clear cookies for any site, including the necessary ones. Blocking those means you will not be able to log in, which is a consequence rather than a fault.
Withdrawing consent is exactly as easy as giving it. That is deliberate, and it is the law.
When we will ask again
If we change what we set, or add a service, we bump the version of this policy and ask again. Your old answer does not roll forward onto a new question.
Otherwise we ask again after 12 months.
Questions: office@syntopia.bg. See also the Privacy Policy and the list of who else touches your data.